We wrote a short post about what we do for supply chain attacks: mendral.com/blog/supply-ch…
A package can be published to npm and pulled into your CI five minutes later. That's the attack window Dependabot-style scanners miss.
Mendral's supply chain agent catches it at PR time. Typo-squatting, malware, suspicious post-install scripts, and packages under 72 hours old


